Page MenuHomePhabricator

Don't apply `security.require-https` to intracluster requests
ClosedPublic

Authored by epriestley on Apr 13 2016, 1:17 PM.
Tags
None
Referenced Files
F19010109: D15696.diff
Nov 22 2025, 2:06 AM
F18951244: D15696.id.diff
Nov 12 2025, 3:41 AM
F18941753: D15696.diff
Nov 11 2025, 11:04 AM
F18941251: D15696.id37825.diff
Nov 11 2025, 9:52 AM
F18941250: D15696.id37818.diff
Nov 11 2025, 9:52 AM
F18919009: D15696.id37832.diff
Nov 9 2025, 11:27 AM
F18903497: D15696.id.diff
Nov 8 2025, 5:19 AM
F18903074: D15696.diff
Nov 8 2025, 3:56 AM
Subscribers
None

Details

Summary

Ref T10784. Currently, if you terminate SSL at a load balancer (very common) and use HTTP beyond that, you have to fiddle with this setting in your premable or a SiteConfig.

On the balance I think this makes stuff much harder to configure without any real security benefit, so don't apply this option to intracluster requests.

Also document a lot of stuff.

Test Plan

Poked around locally but this is hard to test outside of a production cluster, I'll vet it more thoroughly on secure.

Diff Detail

Repository
rP Phabricator
Branch
crepo8
Lint
Lint Passed
Unit
Tests Passed
Build Status
Buildable 11686
Build 14630: Run Core Tests
Build 14629: arc lint + arc unit

Event Timeline

epriestley retitled this revision from to Don't apply `security.require-https` to intracluster requests.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: chad.
chad edited edge metadata.
chad added inline comments.
src/docs/user/cluster/cluster.diviner
96

accessing? or access to?

This revision is now accepted and ready to land.Apr 13 2016, 4:28 PM
epriestley edited edge metadata.
  • Add missing "access to".
This revision was automatically updated to reflect the committed changes.